News

Cisco patches critical Nexus 9000 switch flaw that gives attackers root

Cisco's PSIRT advisory cisco-sa-n9k-s1-rce-EH8dEtr covers CVE-2026-20212, a CVSS 9.8 flaw in the Silicon One integration on Nexus 9000 switches. Software updates are available, it is not in CISA's KEV catalog, and the blast radius is ten product IDs rather than the whole Nexus 9000 line.

Cisco patches critical Nexus 9000 switch flaw that gives attackers root

Cisco has published a PSIRT advisory for CVE-2026-20212, a remote code execution flaw in the Silicon One integration on Nexus 9000 switches that carries a CVSS 3.1 base score of 9.8. Software updates are already available.

This is a first-party vendor advisory with a fix, not an intrusion. Cisco PSIRT says explicitly it is "not aware of any public announcements or malicious use" of the vulnerability. It is not a zero-day, and it is not in CISA's Known Exploited Vulnerabilities catalog. Cisco also notes it was found during the resolution of a Cisco TAC support case, not by an external researcher and not from an incident.

What is exposed

On an affected switch, TCP ports 43210 and 43211 are reachable in the default Layer 3 VRF. Crafted input to those ports can run as code with root privileges, and can also crash the S1HAL process, which can reload the device. The severity vector, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflects a network-reachable flaw with no authentication and no user interaction, which is why it scores at the top of the scale, in the same tier as the ServiceNow AI platform flaws earlier this cycle.

The blast radius is narrower than it looks

This is the fact the headlines flatten. The flaw only affects Nexus 9000 switches that contain a Silicon One ASIC. Cisco lists exactly ten affected product identifiers: N9324C-SE1U, N9348Y2C6D-SE1U, N9364E-SG2-O, N9364E-SG2-Q, N9396T12C-SE1, N9348Y12C-SE1, N9396Y12C-SE1, N9336C-SE1, N9K-C9804 and N9K-C9808. Operators find theirs with the show module command.

Cisco's own advisory then runs a long "confirmed not vulnerable" list. Nexus 3000 Series Switches are on it, as are Nexus 7000, MDS 9000, the ACI-mode Nexus 9000 fabric switches, the Firepower and Secure Firewall lines, and the UCS Fabric Interconnects. Nexus 9000 models without a Silicon One ASIC are explicitly not affected. So the exposure is ten product IDs, not the whole Nexus 9000 family.

Scope from Cisco's list, not the aggregator title

Third-party databases are describing this more broadly than Cisco does. CIRCL's vulnerability-lookup entry titles it "Cisco Nexus 3000 and 9000 Series Switches Silicon One Hardware Abstraction Layer Remote Code Execution Vulnerability," pulling Nexus 3000 into the headline. Cisco's own advisory lists Nexus 3000 Series Switches under products confirmed not vulnerable. Scope your exposure from Cisco's ten product IDs, not from the aggregator title.

There is no single version number to chase

Cisco publishes no one fixed release in the advisory. It routes operators to the Cisco Software Checker for the first fixed release for their platform and train, so the version you need depends on what you run. Cisco has also shipped a Live Protect shield for CVE-2026-20212 as a temporary mitigation for NX-OS, and is clear that a shield only bridges the gap until a fixed release is scheduled. If you cannot patch immediately, the advisory's workaround is an infrastructure ACL that permits only required management and control-plane traffic, or an iACL that explicitly denies TCP to locally configured IPs on destination ports 43210 and 43211.

This is a cleaner situation than the network-gear stories that turned into hunts, like Fire Ant moving onto Cisco IOS XR routers or the PaperCut zero-day that shipped as an emergency patch mid-exploitation. Here you have a fix in hand before anyone weaponized it, which is the whole point of moving now.

What a network team does tonight

In order. Run show module across your fleet and check every result against the ten affected product IDs. If none match, you are done. If any switch is on the list, apply the iACL that denies TCP to your local IPs on destination ports 43210 and 43211 tonight, or enable the Live Protect shield, to close the window while you work. Then pull your platform's first fixed release from the Cisco Software Checker and schedule the upgrade. The order matters: confirm exposure, deny the ports, then patch on your own maintenance clock rather than in a panic.

Cyberpresso: daily cyber & AI brief

Free daily newsletter, read in 5 minutes.

Subscribe free